IP address


.05544.220.188.166scanner-44-220-188-166.reposify.net
Shodan(more info)
Passive DNS
Tags: IP in hostname
IP blacklists
Turris greylist
44.220.188.166 is listed on the Turris greylist blacklist.

Description: Greylist is the output of the Turris research project by CZ.NIC,<br>which collects data of malicious IPs.
Type of feed: primary (feed detail page)

Last checked at: 2026-01-29 22:15:00.167000
Was present on blacklist at: 2026-01-29 22:15
Spamhaus SBL CSS
44.220.188.166 is listed on the Spamhaus SBL CSS blacklist.

Description: The Spamhaus CSS is part of the SBL. CSS listings will have return code 127.0.0.3 to differentiate from regular SBL listings, which have return code 127.0.0.2.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-04-28 13:42:00.532000
Was present on blacklist at: 2026-02-10 13:42, 2026-02-24 13:42, 2026-04-07 13:42, 2026-04-14 13:42, 2026-04-28 13:42
DataPlane SMTP greeting
44.220.188.166 is listed on the DataPlane SMTP greeting blacklist.

Description: DataPlane.org is a community-powered Internet data, feeds,<br>and measurement resource for operators, by operators. IPs that are<br>identified as SMTP clients issuing unsolicited HELO or EHLO commands.
Type of feed: primary (feed detail page)

Last checked at: 2026-02-26 11:10:00.973000
Was present on blacklist at: 2026-02-19 15:10, 2026-02-19 19:10, 2026-02-19 23:10, 2026-02-20 03:10, 2026-02-20 07:10, 2026-02-20 11:10, 2026-02-20 15:10, 2026-02-20 19:10, 2026-02-20 23:10, 2026-02-21 03:10, 2026-02-21 07:10, 2026-02-21 11:10, 2026-02-21 15:10, 2026-02-21 19:10, 2026-02-21 23:10, 2026-02-22 03:10, 2026-02-22 07:10, 2026-02-22 11:10, 2026-02-22 15:10, 2026-02-22 19:10, 2026-02-22 23:10, 2026-02-23 03:10, 2026-02-23 07:10, 2026-02-23 11:10, 2026-02-23 15:10, 2026-02-23 19:10, 2026-02-23 23:10, 2026-02-24 03:10, 2026-02-24 07:10, 2026-02-24 11:10, 2026-02-24 15:10, 2026-02-24 19:10, 2026-02-24 23:10, 2026-02-25 03:10, 2026-02-25 07:10, 2026-02-25 11:10, 2026-02-25 15:10, 2026-02-25 19:10, 2026-02-25 23:10, 2026-02-26 03:10, 2026-02-26 07:10, 2026-02-26 11:10
DataPlane SSH conn
44.220.188.166 is listed on the DataPlane SSH conn blacklist.

Description: DataPlane.org is a community-powered Internet data, feeds,<br>and measurement resource for operators, by operators. IP addresses that<br>has been seen initiating an unsolicited SSH connection to a remote host.
Type of feed: primary (feed detail page)

Last checked at: 2026-02-28 15:10:06.633000
Was present on blacklist at: 2026-01-28 15:10, 2026-01-28 19:10, 2026-01-29 03:10, 2026-01-29 07:10, 2026-01-29 15:10, 2026-01-29 19:10, 2026-01-30 03:10, 2026-01-30 07:10, 2026-01-30 15:10, 2026-01-30 19:10, 2026-01-31 03:10, 2026-01-31 07:10, 2026-01-31 15:10, 2026-01-31 19:10, 2026-02-01 03:10, 2026-02-01 07:10, 2026-02-01 15:10, 2026-02-21 19:10, 2026-02-21 23:10, 2026-02-22 03:10, 2026-02-22 07:10, 2026-02-22 11:10, 2026-02-22 15:10, 2026-02-22 19:10, 2026-02-22 23:10, 2026-02-23 03:10, 2026-02-23 07:10, 2026-02-23 11:10, 2026-02-23 15:10, 2026-02-23 19:10, 2026-02-23 23:10, 2026-02-24 03:10, 2026-02-24 07:10, 2026-02-24 11:10, 2026-02-24 15:10, 2026-02-24 19:10, 2026-02-24 23:10, 2026-02-25 03:10, 2026-02-25 07:10, 2026-02-25 11:10, 2026-02-25 15:10, 2026-02-25 19:10, 2026-02-25 23:10, 2026-02-26 03:10, 2026-02-26 07:10, 2026-02-26 11:10, 2026-02-26 15:10, 2026-02-26 19:10, 2026-02-26 23:10, 2026-02-27 03:10, 2026-02-27 07:10, 2026-02-27 11:10, 2026-02-27 15:10, 2026-02-27 19:10, 2026-02-28 03:10, 2026-02-28 07:10, 2026-02-28 15:10
Echelon TLS/SSL crawler
44.220.188.166 is listed on the Echelon TLS/SSL crawler blacklist.

Description: TLS/SSL connection fingerprinting detected via Suricata
Type of feed: primary (feed detail page)

Last checked at: 2026-04-22 09:40:00.996000
Was present on blacklist at: 2026-03-24 10:40, 2026-03-25 10:40, 2026-03-26 10:40, 2026-03-27 10:40, 2026-03-28 10:40, 2026-03-29 09:40, 2026-03-30 09:40, 2026-03-31 09:40, 2026-04-14 09:40, 2026-04-15 09:40, 2026-04-16 09:40, 2026-04-17 09:40, 2026-04-19 09:40, 2026-04-20 09:40, 2026-04-21 09:40, 2026-04-22 09:40

Threat categories

TLRoleCategoryDetails
27 src login protocol: ftp
port: 21
25 src scan

Warden events (23)
2026-04-21
IntrusionUserCompromise (node.cfb4f7): 1
2026-04-20
IntrusionUserCompromise (node.cfb4f7): 1
2026-04-18
IntrusionUserCompromise (node.cfb4f7): 2
2026-04-17
IntrusionUserCompromise (node.cfb4f7): 1
2026-04-15
IntrusionUserCompromise (node.cfb4f7): 1
2026-04-14
IntrusionUserCompromise (node.cfb4f7): 1
2026-04-12
IntrusionUserCompromise (node.cfb4f7): 1
2026-04-11
IntrusionUserCompromise (node.cfb4f7): 1
2026-04-09
IntrusionUserCompromise (node.cfb4f7): 1
2026-04-05
IntrusionUserCompromise (node.cfb4f7): 1
2026-03-29
IntrusionUserCompromise (node.cfb4f7): 2
2026-03-26
IntrusionUserCompromise (node.cfb4f7): 1
2026-03-13
IntrusionUserCompromise (node.cfb4f7): 1
2026-03-12
IntrusionUserCompromise (node.cfb4f7): 1
2026-03-09
IntrusionUserCompromise (node.cfb4f7): 1
2026-03-08
IntrusionUserCompromise (node.cfb4f7): 1
2026-03-07
IntrusionUserCompromise (node.cfb4f7): 2
2026-02-24
IntrusionUserCompromise (node.cfb4f7): 1
2026-02-21
IntrusionUserCompromise (node.cfb4f7): 2
Origin AS
AS14618 - AMAZON-AES
BGP Prefix
44.192.0.0/11
geo
United States, Ashburn
🕑 America/New_York
hostname
scanner-44-220-188-166.reposify.net
hostname_class
['ip_in_hostname']
Address block ('inetnum' or 'NetRange' in whois database)
44.192.0.0 - 44.255.255.255
last_activity
2026-04-21 10:54:50
last_warden_event
2026-04-21 10:54:50
rep
0.05476190476190476
reserved_range
0
Shodan's InternetDB
Open ports: 80
Tags: cloud
CPEs:
ts_added
2025-12-02 13:41:59.691000
ts_last_update
2026-04-28 13:42:00.877000

Warden event timeline

DShield event timeline

Presence on blacklists